nerdexam
EC-Council

712-50 · Question #151

A department within your company has proposed a third party vendor solution to address an urgent, critical business need. As the CISO you have been asked to accelerate screening of their security…

The correct answer is B. Vendor provided attestation of the detailed security controls from a reputable accounting firm. Option B is correct because a third-party attestation from a reputable accounting firm (e.g., a SOC 2 report from a CPA firm) provides independent, objective verification of the vendor's security controls - exactly what a CISO needs to make a fast but credible risk decision…

Strategic Planning, Finance, Procurement, and Vendor Management

Question

A department within your company has proposed a third party vendor solution to address an urgent, critical business need. As the CISO you have been asked to accelerate screening of their security control claims. Which of the following vendor provided documents is BEST to make your decision:

Options

  • AVendor's client list of reputable organizations currently using their solution
  • BVendor provided attestation of the detailed security controls from a reputable accounting firm
  • CVendor provided reference from an existing reputable client detailing their implementation
  • DVendor provided internal risk assessment and security control documentation

How the community answered

(28 responses)
  • A
    11% (3)
  • B
    79% (22)
  • C
    4% (1)
  • D
    7% (2)

Explanation

Option B is correct because a third-party attestation from a reputable accounting firm (e.g., a SOC 2 report from a CPA firm) provides independent, objective verification of the vendor's security controls - exactly what a CISO needs to make a fast but credible risk decision. Option A (client list) only confirms popularity, not security posture - plenty of breached vendors had impressive client rosters. Option C (client reference) is anecdotal and reflects one organization's experience with implementation, not a formal control assessment. Option D (internal documentation) is self-reported and unverified, giving you only the vendor's word about their own controls.

Memory tip: Think "trust but verify" - and who's doing the verifying matters. Only option B puts an independent, accountable third party on the line. When you see "attestation from a reputable firm," that's the auditor's reputation at stake, not just the vendor's.

Topics

#vendor risk management#third-party attestation#security controls audit#vendor due diligence

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice